CNNVD-202602-1258 Information

CNNVD ID

CNNVD-202602-1258

CVE-2026-25918

  • CNNVD Published: 2026-02-09

Description (Chinese)

unity-cli是RageAgainstThePixel开源的一个Unity游戏引擎的命令行实用程序。 unity-cli 1.8.2之前版本存在日志信息泄露漏洞,该漏洞源于sign-package命令以明文记录敏感凭据,可能导致凭据泄露。

Description (English)

Unity-cli is a command-line application for a Unity game engine from RageAgainst ThePixel. Prior to version 1.8.2, there was a leak in log information, which originated from a sign-package order to explicitly record sensitive evidence, which could lead to disclosure.

Vulnerability Type

日志信息泄露

Affected Vendor

RageAgainstThePixel

Published

2026-02-09

Last Modified

2026-02-24

References

https://github.com/RageAgainstThePixel/unity-cli/commit/8d4d67b23d7c5fd8f00df3f0f10bec2961c95342 https://github.com/RageAgainstThePixel/unity-cli/releases/tag/v1.8.2 https://github.com/RageAgainstThePixel/unity-cli/security/advisories/GHSA-4255-c27h-62m5

Patch

https://github.com/RageAgainstThePixel/unity-cli/releases

Share on: